IP Library Granted Patent US 11,659,007
Granted Patent B2
US 11,659,007 · App. 17/532,764 · Granted May 23, 2023

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: ReliaQuest Holdings, LLC
H04L63/20H04L41/024H04L63/145H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,659,007
App. No.
17/532,764
Granted
May 23, 2023
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; defining a plurality of subsystem-specific queries on a unified platform concerning the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems.

Claims (117)

1. A computer-implemented method, executed on a computing device, comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform, wherein each security-relevant subsystem is deployed within the computing platform and monitors the operation and activity within the computing platform and wherein each security-relevant subsystems monitors and logs their activity with respect to the computing platform;

defining a plurality of subsystem-specific queries on a unified platform concerning the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and

providing the plurality of subsystem-specific queries to the plurality of security-relevant sub systems.

2. The computer-implemented method of claim 1 wherein the defined execution schedule is a default execution schedule configured to be revisable by a third-party.

3. The computer-implemented method of claim 1 wherein the defined execution schedule includes one or more of:

a defined execution time;

a defined execution date;

a defined execution frequency; and

a defined execution scope.

4. The computer-implemented method of claim 1 further comprising:

determining that one or more of the plurality of subsystem-specific queries failed to execute properly, thus defining one or more failed subsystem-specific queries; and

reexecuting the one or more failed subsystem-specific queries.

5. The computer-implemented method of claim 1 further comprising:

defining a unified query on the unified platform concerning the plurality of security-relevant sub systems;

denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries.

6. The computer-implemented method of claim 5 wherein denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries includes:

translating a syntax of the unified query to a syntax of each of the plurality of subsystem-specific queries.

7. The computer-implemented method of claim 1 further comprising:

receiving a plurality of subsystem-specific results sets from the plurality of security-relevant subsystems that were generated in response to the plurality of subsystem-specific queries.

8. The computer-implemented method of claim 7 further comprising:

normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set; and

providing the unified result set to a third-party.

9. The computer-implemented method of claim 8 wherein normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set includes:

translating a syntax of each of the plurality of subsystem-specific results sets to a syntax of the unified result set.

10. The computer-implemented method of claim 1 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

11. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform, wherein each security-relevant subsystem is deployed within the computing platform and monitors the operation and activity within the computing platform and wherein each security-relevant subsystems monitors and logs their activity with respect to the computing platform;

defining a plurality of subsystem-specific queries on a unified platform concerning the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and

providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems.

12. The computer program product of claim 11 wherein the defined execution schedule is a default execution schedule configured to be revisable by a third-party.

13. The computer program product of claim 11 wherein the defined execution schedule includes one or more of:

a defined execution time;

a defined execution date;

a defined execution frequency; and

a defined execution scope.

14. The computer program product of claim 11 further comprising:

determining that one or more of the plurality of subsystem-specific queries failed to execute properly, thus defining one or more failed subsystem-specific queries; and

reexecuting the one or more failed subsystem-specific queries.

15. The computer program product of claim 11 further comprising:

defining a unified query on the unified platform concerning the plurality of security-relevant sub systems;

denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries.

16. The computer program product of claim 15 wherein denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries includes:

translating a syntax of the unified query to a syntax of each of the plurality of subsystem-specific queries.

17. The computer program product of claim 11 further comprising:

receiving a plurality of subsystem-specific results sets from the plurality of security-relevant subsystems that were generated in response to the plurality of subsystem-specific queries.

18. The computer program product of claim 17 further comprising:

normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set; and

providing the unified result set to a third-party.

19. The computer program product of claim 18 wherein normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set includes:

translating a syntax of each of the plurality of subsystem-specific results sets to a syntax of the unified result set.

20. The computer program product of claim 11 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

21. A computing system including a processor and memory configured to perform operations comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform, wherein each security-relevant subsystem is deployed within the computing platform and monitors the operation and activity within the computing platform and wherein each security-relevant subsystems monitors and logs their activity with respect to the computing platform;

defining a plurality of subsystem-specific queries on a unified platform concerning the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and

providing the plurality of subsystem-specific queries to the plurality of security-relevant sub systems.

22. The computing system of claim 21 wherein the defined execution schedule is a default execution schedule configured to be revisable by a third-party.

23. The computing system of claim 21 wherein the defined execution schedule includes one or more of:

a defined execution time;

a defined execution date;

a defined execution frequency; and

a defined execution scope.

24. The computing system of claim 21 further comprising:

determining that one or more of the plurality of subsystem-specific queries failed to execute properly, thus defining one or more failed subsystem-specific queries; and

reexecuting the one or more failed subsystem-specific queries.

25. The computing system of claim 21 further comprising:

defining a unified query on the unified platform concerning the plurality of security-relevant sub systems;

denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries.

26. The computing system of claim 25 wherein denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries includes:

translating a syntax of the unified query to a syntax of each of the plurality of subsystem-specific queries.

27. The computing system of claim 21 further comprising:

receiving a plurality of subsystem-specific results sets from the plurality of security-relevant subsystems that were generated in response to the plurality of subsystem-specific queries.

28. The computing system of claim 27 further comprising:

normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set; and

providing the unified result set to a third-party.

29. The computing system of claim 28 wherein normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set includes:

translating a syntax of each of the plurality of subsystem-specific results sets to a syntax of the unified result set.

30. The computing system of claim 21 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2021
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 058187/0400 →
Continuity (2)
Provisional Application 63117180 · Nov 23, 2020
Related Publication 20220166801A1 · May 26, 2022